RatedWithAI

RatedWithAI

Accessibility scanner

AI Legal & ComplianceAugust 3, 2026

You Can Violate Export Controls Without Shipping Anything: AI Startups and the Deemed Export Problem

Founders hear "export controls" and picture crates, customs forms and defense contractors. The regime that actually reaches AI companies works differently. It attaches to technology and software, it treats giving a foreign national access as an export even when everyone involved is sitting in California, and its most common trigger at an AI startup is a routine onboarding ticket.

No border required
Release to a foreign national in the US can be treated as an export
Strict liability regime
Intent is not an element; not knowing the classification is not a defense
Diligence flashpoint
Acquirers and enterprise buyers now ask; no documented answer reads as risk

The Mental Model Is Wrong Before the Facts Are

Export control law in the United States is administered largely through the Export Administration Regulations, which govern items on the Commerce Control List along with a broad residual category covering most other commercial goods, software and technology. Two features of that structure surprise software founders. The first is that "technology" includes information required for development, production or use of a controlled item — designs, specifications, know-how — not merely a compiled artifact. The second is that "export" includes release to a foreign person, wherever that person is standing.

Put those together and the shape of the risk changes completely. A company with no physical product, no international entity and no shipping department can still create an export event by adding an engineer to a repository. That is the deemed export concept, and it has existed for decades in semiconductor, aerospace and encryption contexts. AI has simply made it relevant to a category of company that never had reason to learn it.

Where the Release Actually Happens

Hiring and Team Structure
  • Foreign-national research staff granted full repository access on day one
  • Offshore contractors and agencies working inside production environments
  • Visiting researchers and academic collaborators in design discussions
  • Acqui-hired teams whose prior access model was never reviewed
  • Interns given the same permission set as full-time engineers
Infrastructure and Compute
  • Training clusters reachable from any jurisdiction with a valid credential
  • Model checkpoints in buckets with organization-wide read access
  • Support and on-call rotations that include staff working abroad
  • Shared partner environments provisioned outside the normal access review
  • Backups and artifact registries replicated to regions nobody chose deliberately
Go-to-Market
  • Self-serve signup with no denied-party or geographic screening
  • Resellers and marketplaces placing the product in destinations you never reviewed
  • Trials issued to prospects whose end use is unknown and unasked
  • Technical documentation gated only by an email address
  • Support engineers walking customers through controlled detail on calls
The Structural Failures
  • No written classification of the company's own core technology
  • Access provisioning owned by whoever is fastest, with no compliance step
  • Policy that exists as a slide, with no record of who read it
  • No screening at renewal, only at first signup
  • Nobody named as owner, so the question surfaces first during diligence

Classification Is a Decision You Are Expected to Have Made

The instinct at a small company is to assume the rules are for someone else and move on. That instinct is usually right on the merits and always wrong on the record. Plenty of AI software falls into low-restriction categories, and material that is genuinely published or publicly available is treated differently from proprietary technology. But those are conclusions, and the regime expects you to reach them deliberately, write them down, and revisit them when the product changes.

The asymmetry is what makes this worth an afternoon. Reaching a documented conclusion that your product is not subject to meaningful restriction costs very little. Having no documented conclusion means that when a customer's security questionnaire, an acquirer's diligence list or a regulator's inquiry arrives, every hire and every integration from the company's history becomes an open question you must reconstruct from memory.

Model Weights: The Part That Keeps Moving

Whether and when trained model weights themselves fall under export restrictions has been among the most contested questions in the regime, and it has moved more than once as policy has shifted between openness and restriction. Chasing the current state of that debate is the wrong project for a startup. The durable move is architectural: keep an inventory of proprietary artifacts, know which storage each one lives in, know precisely who can pull it and from where, and make that access revocable in an afternoon. A company built that way can absorb a rule change. A company where the latest checkpoint is in a bucket everyone can read cannot comply with any rule, current or future.

The Customer Side Nobody Screens

Restricted party lists and embargoed destinations apply to a nineteen-dollar monthly subscription exactly as they apply to a seven-figure enterprise deal. The difference is that the enterprise deal passes through a human who might think about it. Self-serve signup is designed specifically to remove that human. Screening at signup and at renewal, geographic controls where required, and end-use terms enforced in the product rather than only in the contract are the three controls that close the gap — and all three are engineering work, not legal work, which is why they tend to be nobody's priority until they are urgent.

A Program Proportionate to a Startup

Establish the Record

  • Classify your core technology and software in writing, with the reasoning and the date
  • Inventory proprietary artifacts — weights, training data, architecture detail — and where each lives
  • Document the access model for repositories, clusters and artifact stores
  • Write a short policy that names the artifacts and the approval path, and collect acknowledgments
  • Name one owner; rotating responsibility produces no record at all

Make It Hold Under Pressure

  • Add denied-party screening to signup, renewal and vendor onboarding
  • Apply geographic controls in the product where the rules require them
  • Gate access to controlled artifacts through a request that leaves a log
  • Review access on a schedule and at offboarding, including contractors and partners
  • Re-run the classification whenever the product materially changes

None of this is legal advice, and the classification questions genuinely warrant counsel who works in this area. What does not warrant counsel is the operational half: knowing what you have, knowing who can reach it, and being able to prove both. That part is yours, and it is the part that determines whether an export question is a two-hour answer or a three-month reconstruction.

Frequently Asked Questions

We are five people with no international customers. Is this premature?

The customer side may be premature; the team side usually is not. Deemed export exposure is created by who has access to your technology, and a five-person team with one foreign-national engineer already has the fact pattern. The proportionate response at that size is a written classification, a documented access model and a named owner — not a compliance department.

Does publishing our model openly remove the problem?

It changes the analysis substantially for the published material, because genuinely published information sits differently under the regulations than proprietary technology. It does not extend to everything else you hold — unreleased checkpoints, training infrastructure, internal evaluation results and roadmap technology remain proprietary. Publishing one artifact is not a company-wide exemption.

Our engineers are on visas. Can we just not hire foreign nationals?

That is both bad business and a legal hazard of its own. US anti-discrimination rules constrain how citizenship status can factor into hiring, and export compliance is not a blanket license to exclude. The workable approach is scoping access to controlled material and, where required, obtaining authorization — not filtering candidates.

Do our cloud provider's controls cover us?

Their controls cover their obligations, not yours. Region selection, access logging and encryption are useful inputs to your program, but the determination of what your technology is and who may receive it stays with you. Read the shared-responsibility model rather than assuming the platform absorbed the question.

What actually happens if we get this wrong?

Enforcement outcomes range widely, from warning letters through substantial civil penalties and, in serious cases, criminal exposure and denial of export privileges. For most startups the more probable harm arrives sooner and commercially: a failed enterprise security review, a diligence finding that reprices a deal, or a partner declining to integrate.

How does this interact with our privacy and AI governance work?

It shares the same substrate — an inventory of what you hold, a map of who can reach it, and a documented decision about each. Teams that build that substrate once can answer export, privacy, security and AI governance questions from the same source. Teams that answer each regime separately rebuild the same map three times and keep three inconsistent copies.

Your Public Pages Describe Controls You May Not Run

Trust centers, security pages and enterprise FAQs routinely make claims about access control, data residency and who can reach customer systems. Those claims are read by the same reviewers who ask export questions, and a page that overstates your controls is worse than a page that says nothing.

See what your site currently claims. Run a free scan and review every page that describes how access to your systems is controlled.

Is your own site ADA compliant?

Run a free WCAG 2.1 AA scan on any public URL. Real axe-core checks in a real browser — instant report, no signup.

Need it watched instead of checked once? Starter is $29/mo for continuous monitoring, audit trails and PDF/CSV exports.